Independent Security Process for File I/O Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security programs for file input and output are complex and difficult to produce and update, requiring extensive professional effort and resources due to the need for multiple security control policies across different execution paths and formats, which complicates their implementation and maintenance.

Innovation Solution

A method and system where a security process runs independently of the main application program, connected to a filter driver that checks events and compares them against security control policies, allowing for centralized policy management and execution, thereby simplifying the production and update of security control policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security control policies are implemented across different execution paths and formats, then security coverage is improved, but system complexity and production difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security control policies into a single unified policy structure that can be executed across different paths. Instead of implementing separate policies for user-level and kernel-level operations, the invention creates one comprehensive security control policy that covers all execution paths, thereby reducing system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security control policy is designed to be universal and multi-functional, capable of handling various security scenarios (file input, file output, directory operations, etc.) through a single policy framework. This universal policy can be applied across different execution contexts without requiring separate specialized policies for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple security control policies in different formats are maintained, then security control capability is improved, but ease of manufacture and update deteriorates

Engineering Contradiction:
Improvesecurity control capabilityVSAvoidproduction ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent enforces homogeneity by requiring all security control policies to be defined in a single standardized format (XML). This eliminates the need to maintain multiple policy formats, making policy creation, validation, and updates significantly easier while preserving comprehensive security control capability through the unified structure.

Inventive Principle:
Principle #33Homogeneity

3Reliability

If comprehensive security control policies are implemented, then data security is improved, but resource consumption and cost increase

Engineering Contradiction:
Improvedata securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts and isolates security control logic into a separate, dedicated security process that operates independently from the main application. This extraction allows the security subsystem to be optimized specifically for security operations, reducing overall resource consumption while maintaining comprehensive data security through dedicated security handling.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8452740B2Method and system for security of file input and output of application programs
Publication Date: 2013.05.28 SOFTCAMP
  • US8452740B2 patent drawing
  • US8452740B2 patent drawing
  • US8452740B2 patent drawing

AI summary

Provided herein is a method and system for the security of the file input and output of application programs. At a security process running step, an application program and an security process are executed independent of a main process of the application program. The security process is connected to a filter driver to control the filter driver. At an event generation step, the filter driver checks an event being processed by the application program, stops the processing of the event, and transfers event information regarding the event to the security process. At a control policy checking step, the security process compares the event information with a corresponding security control policy, and transfers the determination of the comparison to the filter driver. At an execution step, the filter driver continues the following processing of the corresponding event in conformity with the determination of the security process.